A 28-year-old Russian national accused of being a core member of the Qilin ransomware group was arrested in Osaka, Japan, in May and reportedly extradited to Germany on 2 October. German authorities wanted him over an attack on a logistics company in September 2024. The suspect is accused of hacking into the company’s systems, encrypting its data and extorting more than $160,000 in cryptocurrency. The report describes these as allegations; it does not say whether the suspect has been convicted.
Qilin, also known as Agenda, has operated since August 2022 as a ransomware-as-a-service group and has attacked organisations worldwide. SecurityWeek reports that it listed 400 victims on its Tor-based leak site during 2025, including Lee Enterprises and pharmaceutical company Inotiv. The group has also been blamed for attacks affecting Synnovis, which disrupted services at several London NHS hospitals, and Asahi Group, where roughly 2 million people’s personal information was compromised.
In June 2025, Qilin was reported to be exploiting CVE-2026-50751, an authentication bypass in Check Point VPN and firewall products. In August, the US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cyberattack after Qilin named it on the group’s leak site.